Poisoning and tracking credentials for phishing web sites
Abstract
Poisoned credentials are entered to the login section of phishing web sites automatically identified as related to a legitimate web site. The poisoned credentials are not valid credentials with respect to the login section of the legitimate web site. Later, a login attempt to the legitimate web site is detected on the enterprise network by a malicious actor making use of the poisoned credentials. Data about a malicious actor is collected using the poisoned credentials including an IP address and a time. A security action can also be taken against the malicious actor with respect to the poisoned credentials.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A computer-implemented method in a phishing security server on an enterprise network, for proactively securing an enterprise network by distributing and tracking poisoned credentials related to the enterprise network on phishing web sites, the method comprising:
receiving an identification of a phishing web site having a login section and corresponding to a legitimate web site having a login section, wherein the legitimate web site is on the enterprise network; entering poisoned credentials to the login section of the phishing web site, wherein the poisoned credentials are not valid credentials with respect to the login section of the legitimate web site; detecting a login attempt to the legitimate web site on the enterprise network by a malicious actor making use of the poisoned credentials; allowing the malicious actor access to a quarantine account on the legitimate web site with the poisoned credentials; collecting data about the malicious actor while interacting with the quarantine account using the poisoned credentials including an Internet Protocol (IP) address and a time, wherein the quarantine account appears to be a legitimate account; and taking a security action against the malicious actor with respect to the poisoned credentials.
2 . The method of claim 1 , wherein the poisoned credentials were transferred to the malicious actor over the Dark Web.
3 . The method of claim 1 , further comprising: sending the data collected about the malicious actor to a cloud-based phishing server to aggregate data collected from different enterprise networks concerning the malicious actor.
4 . The method of claim 1 , wherein the step of collecting data about the malicious actor comprises collecting an IP address and a time stamp.
5 . A non-transitory computer-readable medium in a phishing security server on an enterprise network, for proactively securing an enterprise network by distributing and tracking poisoned credentials related to the enterprise network on phishing web sites, the method comprising:
receiving an identification of a phishing web site having a login section and corresponding to a legitimate web site having a login section, wherein the legitimate web site is on the enterprise network; entering poisoned credentials to the login section of the phishing web site, wherein the poisoned credentials are not valid credentials with respect to the login section of the legitimate web site; detecting a login attempt to the legitimate web site on the enterprise network by a malicious actor making use of the poisoned credentials; allowing the malicious actor access to a quarantine account on the legitimate web site with the poisoned credentials; collecting data about the malicious actor while interacting with the quarantine account using the poisoned credentials including an Internet Protocol (IP) address and a time, wherein the quarantine account appears to be a legitimate account; and taking a security action against the malicious actor with respect to the poisoned credentials.
6 . The method of claim 5 , wherein the poisoned credentials were transferred to the malicious actor over the Dark Web.
7 . The method of claim 5 , further comprising: sending the data collected about the malicious actor to a cloud-based phishing server to aggregate data collected from different enterprise networks concerning the malicious actor.
8 . The method of claim 5 , wherein the step of collecting data about the malicious actor comprises collecting an IP address and a time stamp.
9 . A phishing security server on an enterprise network, to proactively secure an enterprise network by distributing and tracking poisoned credentials related to the enterprise network on phishing web sites, the phishing security server comprising:
a processor; a network interface communicatively coupled to the processor and to the enterprise network; and a memory, communicatively coupled to the processor and storing source code executed by the processor, comprising:
a phishing detector to receive an identification of a phishing web site having a login section and corresponding to a legitimate web site having a login section, wherein the legitimate web site is on the enterprise network;
a credentials poisoning module to enter poisoned credentials to the login section of the phishing web site, wherein the poisoned credentials are not valid credentials with respect to the login section of the legitimate web site;
a login detector to detect a login attempt to the legitimate web site on the enterprise network by a malicious actor making use of the poisoned credentials, wherein the login detector allows the malicious actor access to a quarantine account on the legitimate web site with the poisoned credentials, and collects data about the malicious actor while interacting with the quarantine account using the poisoned credentials including an Internet Protocol (IP) address and a time, wherein the quarantine account appears to be a legitimate account; and
a security action module to take a security action against the malicious actor with respect to the poisoned credentials.Join the waitlist — get patent alerts
Track US12531901B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.